Bound on refund size for static unbounded-claim identification

Prove a general bound on the refund parameter ω that guarantees the identification of the static no-refund transformer T⊥ with the implementation's vacuous-bound transformer T1.0 throughout all reachable runtime executions.

Background

The formal static semantics represents an unbound claim with T⊥, while the implementation represents it using a vacuous declared bound of 1 and T1.0. These transformers coincide only while wealth remains below 1/i. The paper proves this condition for the static trace under suitable bounds, but runtime refunds can increase wealth beyond that threshold when ω is unrestricted. A general refund bound that closes this gap has not been proved.

References

We have not proved a bound on $\omega$ that closes it, and we do not claim one; the identification of $T_{1.0}$ with $T_\bot$ in \lstinline|Plan.audit| is sound under the stated invariant and is an open gap without it.

Tacet: A Language and Type System for Automatic Statistical Validity Accounting  (2608.27451 - Abuah, 27 Aug 2026) in Appendix, Section “Operational Semantics of the Runtime Monitor and the Checker,” subsection “The identification of T1.0 with T⊥”; Section 7, subsection “Unbounded refund”